ZeroFox Daily Intelligence Brief - October 5, 2023
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 5, 2023
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cisco Addresses Root Credential Access Vulnerability
- Apple Releases Emergency Updates for Kernel-Level Bug
- Lyca Mobile Blames Cyberattack for Network Disruption
- Data broker / initial-access broker / hacktivist group: XSS user spartanking and GhostSec
- Vulnerabilities: CVE-2023-4911 and CVE-2023-26237
- Exploits: CVE-2021-42694 and CVE-2021-34527
- Breaches: Telegram: "ArtHouse Cloud FREE.zip" Botnet Breach
Cisco Addresses Root Credential Access Vulnerability
A critical set of vulnerabilities in the TorchServe AI tool, dubbed "ShellTorch," impacts tens of thousands of internet-exposed servers. TorchServe, maintained by Meta and Amazon, serves PyTorch ML models in production and is used by academic researchers and tech giants such as Amazon, OpenAI, Tesla, Azure, Google, and Intel. The flaws could lead to unauthorized server access and remote code execution. Attacks can be prevented by configuring servers to bind exclusively to local hosts and to fetch models only from trusted domains. Meta and Amazon have acknowledged the issue and encourage developers to use the latest version of TorchServe (0.8.2).
Apple Releases Emergency Updates for Kernel-Level Bug
American semiconductor company Qualcomm has disclosed that four vulnerabilities are possibly under limited, targeted exploitation. The company has issued patches for the bugs—which affect Adreno GPU and Compute DSP drivers—and urges original equipment manufacturers (OEMs) to deploy security updates for users at the earliest possible. While details of one of the vulnerabilities (CVE-2022-22071) were disclosed in Qualcomm’s May 2022 public bulletin, the other three (CVE-2023-33107, CVE-2023-33106, and CVE-2023-33063) will be elaborated in the December 2023 issue.
Lyca Mobile Blames Cyberattack for Network Disruption
British mobile operator Lyca Mobile has disclosed that a cyberattack led to service disruption for millions of users. Lyca Mobile, which operates in over 60 countries, said that all markets except for the United States, Australia, Ukraine, and Tunisia were affected by the attack. Customers reported disruptions in national and international calling, SMS, credit top up, and customer support. While Lyca has not revealed details of the incident, mobile telecommunication services have been restored in all markets; some unspecified operational services are reportedly still being restored.
THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS
- XSS user spartanking: Claims data breach on New York-based company GoodAccountants[.]com.
- GhostSec:: Leaks 459,000 records (including PII) purportedly from EuroBets Casino
VULNERABILITIES
- CVE-2023-4911:: arm64 boot CPUs may lack speculative execution protections
- CVE-2023-26237:: An issue was discovered in WatchGuard EPDR 8.0.21.0002.
EXPLOITS
- CVE-2021-42694: Inappropriate Encoding for Output Context.
- CVE-2021-34527: Print Spooler Remote DLL Injection.
BREACHES
- Telegram: "ArtHouse Cloud FREE.zip" Botnet Breach: (41,399 Records)| Email address, user activity, and password.
Tags: DIB, tlp:green